
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 1
Wireless Penetration Testing CPENT Practice Questions (Page 9)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
50questions here
10free pages
10concepts
Questions 41–45
- 41
You have successfully cracked the WPA2-PSK passphrase of a corporate wireless network and connected your laptop. You need to perform post-exploitation enumeration, but you want to avoid detection by the network's intrusion detection system (IDS). Which approach would be the most stealthy for host discovery?
Select an answer first - 42
During a red-team engagement, you need to capture credentials from employees connecting to the corporate Wi-Fi. The corporate network uses WPA2-Enterprise with PEAP-MSCHAPv2. You set up an evil twin AP with the same SSID and a captive portal that mimics the corporate login page. What additional step is essential to force clients to connect to your rogue AP?
Select an answer first - 43
What is an evil twin attack in wireless penetration testing?
Select an answer first - 44
Which wireless security protocol introduced the Simultaneous Authentication of Equals (SAE) handshake to provide forward secrecy and resistance to offline dictionary attacks?
Select an answer first - 45
You are testing a small office that uses a WPA2-PSK network. The access point has WPS enabled with default settings. Your initial attempt to brute-force the WPS PIN using reaver fails after several PIN attempts, and the AP stops responding to WPS probes. What is the most likely cause and the appropriate next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.